CVE-2026-81809: CWE-89 SQL Injection in Paytm Payment Gateway
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks.
AI Analysis
Technical Summary
The Paytm Payment Gateway WordPress plugin prior to version 2.8.9 does not properly sanitize data received from payment callbacks before incorporating it into SQL queries. This improper escaping combined with a forgeable integrity check when the gateway is enabled without credentials enables unauthenticated users to perform SQL injection attacks against the backend database. The vulnerability is tracked as CVE-2026-81809 and is classified under CWE-89 (SQL Injection).
Potential Impact
Successful exploitation could allow an unauthenticated attacker to execute arbitrary SQL commands on the database, potentially leading to data disclosure or modification. The CVSS 3.1 score is 7.5 (high), reflecting network attack vector, high complexity, no privileges required, no user interaction, and impact on confidentiality (high) and integrity (low), with no impact on availability.
Mitigation Recommendations
A fixed version 2.8.9 or later should be applied to remediate this vulnerability. Since no patch links are provided in the input, verify with the vendor or official plugin repository for the availability of the update. Until patched, ensure the gateway is not enabled without credentials to prevent exploitation of the forgeable integrity check.
CVE-2026-81809: CWE-89 SQL Injection in Paytm Payment Gateway
Description
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and the integrity check on those callbacks can be forged when the gateway is enabled without credentials, allowing unauthenticated users to perform SQL injection attacks.
CVSS v3.1
Score 7.5high
Affected software
Paytm Payment Gateway
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Paytm Payment Gateway WordPress plugin prior to version 2.8.9 does not properly sanitize data received from payment callbacks before incorporating it into SQL queries. This improper escaping combined with a forgeable integrity check when the gateway is enabled without credentials enables unauthenticated users to perform SQL injection attacks against the backend database. The vulnerability is tracked as CVE-2026-81809 and is classified under CWE-89 (SQL Injection).
Potential Impact
Successful exploitation could allow an unauthenticated attacker to execute arbitrary SQL commands on the database, potentially leading to data disclosure or modification. The CVSS 3.1 score is 7.5 (high), reflecting network attack vector, high complexity, no privileges required, no user interaction, and impact on confidentiality (high) and integrity (low), with no impact on availability.
Mitigation Recommendations
A fixed version 2.8.9 or later should be applied to remediate this vulnerability. Since no patch links are provided in the input, verify with the vendor or official plugin repository for the availability of the update. Until patched, ensure the gateway is not enabled without credentials to prevent exploitation of the forgeable integrity check.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-08-27T12:32:37.159Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abe7497a43b0b3b89bd1d1d
Added to database: 10/01/2026, 14:56:23 UTC
Last enriched: 10/01/2026, 15:24:04 UTC
Last updated: 10/02/2026, 01:16:30 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.